Privacy Policy
Last updated: 6 August 2026
At a Glance
Adult Day Centre is responsible for looking after your personal data. We collect and use your information to deliver caring day centre services, manage enrolments, and run this website smoothly. This privacy policy clearly explains what information we collect, why we need it, how long we store it, and the rights you have under UK GDPR.
1 Introduction
Adult Day Centre ("we", "us", or "our") is dedicated to protecting your privacy and personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This privacy policy explains how we collect, use, store, share, and protect your personal information when you visit our website at www.adultdaycentre.org.uk, use our online Portal, or access our adult day care services.
This policy applies to everyone who interacts with us, including individuals who use our services, their families, representatives, carers, staff, volunteers, and website visitors. Please take a moment to read through it so you understand how we look after your information.
2 Who We Are & Data Controller
Adult Day Centre is the data controller for the personal information we hold. This means we decide how and why your personal data is collected, used, and protected.
Data Controller
Adult Day Centre
VaLu Business Park, Ashbourne Rd
Cheadle, Staffordshire, ST10 1HF
Tel: 0800 612 8825
Email: contact@adultdaycare.org.uk
We have appointed a Data Protection Officer (DPO) to oversee our data care. If you have any questions or wish to exercise your rights, please email our DPO at dpo@adultdaycentre.org.uk.
3 Data We Collect
We collect different types of personal information depending on how you interact with us:
3.1 Individual Care Data
- Identity details: name, date of birth, gender, address, and National Insurance number (where required for local authority funding);
- Contact details: phone number, email address, and emergency contacts;
- Health and care details: medical conditions, medications, mobility requirements, dietary needs, allergies, mental capacity assessments, and care plan details;
- Assessment records: care needs assessment findings, risk assessments, and social worker or GP reports;
- Financial details: bank details for fee payments, local authority funding references, and payment history;
- Attendance records: session booking logs, attendance history, and transport arrangements;
- Photographs: activity photos taken only with explicit written consent for newsletters, social media, or internal display.
3.2 Family, Carer & Representative Data
- Name, relationship to the individual, and contact details;
- Power of Attorney or legal authority documentation;
- Communication preferences and record of correspondence.
3.3 Website Visitor Data
- Technical data: IP address, browser type and version, device type, operating system, and screen resolution;
- Usage data: pages visited, time spent on pages, links clicked, navigation paths, and referral web pages;
- Location data: approximate town or region based on IP address (never precise GPS location);
- Form submissions: name, email address, and message details when contacting us through online forms;
- Portal account data: username, email address, login timestamps, and account activity within our online Portal.
3.4 Staff & Volunteer Data
- Identity details, contact information, Disclosure and Barring Service (DBS) certificate details, training records, and employment history;
- Emergency contact details and right-to-work documentation.
4 How We Collect Your Data
We gather personal information through several channels:
- Directly from you: when you fill in an enrolment form, contact us via our website, telephone or email us, or register for our Portal;
- From your representative: when a family member or carer provides details on behalf of an individual;
- From health and care professionals: with your agreement, we may receive details from your GP, district nurse, social worker, or other care providers to build an accurate care plan;
- From local authorities: when care is funded by a local council, we receive necessary care assessments and funding references;
- Automatically via our website: cookies and basic analytics gather technical usage information when you browse our site (see Section 7);
- From trusted service partners: payment processors, secure web hosts, and analytics providers processing data strictly on our behalf.
5 How We Use Your Data
We use personal information to deliver high-quality care and run our day centre safely. Specifically, we use your information for:
Service Delivery
- Assessing suitability and creating personalised care plans
- Providing daily care, activities, meals, support, and transport
- Managing session bookings, schedules, and attendance
- Communicating with you or your family regarding care
Administration & Finance
- Processing fee payments, invoices, and receipts
- Managing local authority funding claims
- Maintaining accurate individual care records
- Managing staff and volunteer records, including DBS checks
Legal & Regulatory Compliance
- Meeting duties under the Care Act 2014 and CQC standards
- Safeguarding vulnerable adults and reporting concerns
- Handling enquiries, feedback, or complaints
- Keeping statutory records required by UK legislation
Website & Portal
- Operating, securing, and enhancing our website and Portal
- Analysing visitor traffic to improve accessibility
- Protecting against security threats
- Sending service updates (only where opted in)
6 Legal Basis for Processing
Data protection law requires us to have a valid legal reason (known as a 'legal basis') to handle your personal information. The legal grounds we rely on include:
| Legal Basis | What It Means | When We Use It |
|---|---|---|
| Consent | You have given clear permission for us to process your data for a specific purpose. | Activity photos, newsletter emails, optional website cookies. |
| Contract | Information is needed to deliver services you have asked us to provide. | Enrolments, fee invoicing, attendance tracking, Portal accounts. |
| Legal Obligation | We are required by law or regulations to keep or share information. | Safeguarding reports, CQC regulatory compliance, DBS checks, tax records. |
| Vital Interests | Information is needed urgently to protect someone's life or health. | Medical emergencies, urgent first aid, calling emergency services. |
| Legitimate Interests | We have a genuine business reason that is fair and does not override your rights. | Website security, service improvements, internal administration. |
| Public Task | Carrying out tasks in the interest of public safety and social care. | Protecting adults at risk under the Care Act 2014. |
When processing relies on your consent, you are free to withdraw that consent at any time by contacting us (see Section 16). Withdrawing consent does not affect the lawfulness of any processing carried out beforehand.
7 Cookies & Tracking Technologies
Our website uses cookies and small data files to recognise your device, remember your settings, analyse how visitors use our site, and improve your overall experience.
7.1 What Are Cookies?
Cookies are small text files saved on your computer or mobile device when you visit a website. They help the site work properly, remember your choices (like font size or login state), and understand how pages are viewed. Cookies cannot harm your computer or access files on your hard drive.
7.2 Types of Cookies We Use
| Cookie Type | Purpose | Duration | Consent? |
|---|---|---|---|
| Strictly Necessary | Essential for website security and basic functions (cookie preferences and Portal login). | Session / persistent | No: required for basic operation. |
| Preference | Remembers your custom settings, such as text size or contrast. | Up to 1 year | Yes: via cookie banner. |
| Analytics | Helps us understand how visitors use our site. | Up to 24 months | Yes: via cookie banner. |
| Marketing | Used to show relevant updates on other websites (if we run campaigns). | Up to 6 months | Yes: via cookie banner. |
7.3 Cookie Consent
When you first visit our website, a banner appears giving you the choice to accept or decline optional cookies. Your choice is remembered in your browser so you are not asked repeatedly on future visits.
You can update your cookie choices at any time by clearing your browser cache or adjusting your browser settings. Please note that turning off necessary cookies may affect website features such as logging into the Portal.
7.4 How to Manage Cookies
You can manage or remove cookies directly through your web browser settings. Links for common browsers:
8 Website Analytics & User Activity Tracking
We use web analytics tools to see how visitors move around our website so we can make it easier to read and navigate. All website analytics data is grouped together and anonymised where possible.
8.1 What We Track
- Page views: which pages people visit and how frequently;
- Visit duration: how long visitors spend reading our site;
- Bounce rate: whether visitors view multiple pages or leave after one page;
- Traffic sources: how visitors found us (search engines, social media, or direct links);
- Device and browser: screen sizes, operating systems, and web browser types;
- Approximate location: general town or region based on IP address, not exact location;
- Click patterns: buttons and links clicked, helping us improve site navigation;
- Form activity: when contact forms are submitted (form contents are handled securely as personal data).
8.2 What We Do Not Track
- We do not track precise GPS locations or home addresses;
- We do not identify individual visitors or build personal browsing profiles;
- We do not sell or share analytics data with advertisers or third parties;
- We do not use analytics to make automated decisions about individuals.
8.3 Analytics Tools We Use
We may use privacy-focused analytics tools that do not set persistent identifying cookies. Where we use tools like Google Analytics, we configure them to anonymise IP addresses and respect Do Not Track signals. Analytics cookies are only set after you give consent via our cookie banner.
9 Who We Share Data With
We may share your personal information with specific parties where it is necessary to deliver our services or meet legal duties:
We never sell your personal data to anyone. All sharing is governed by data processing agreements and limited to what is necessary for the purpose described.
10 International Data Transfers
Our services are based in the UK. Some of our technology providers (such as web hosting or analytics) may process data outside the UK. Where this happens, we ensure appropriate safeguards are in place, such as UK adequacy regulations or Standard Contractual Clauses, to protect your data to the same standard required under UK GDPR.
We will not transfer your personal data outside the UK without ensuring that appropriate legal protections are in place.
11 Data Retention
We only keep personal information for as long as necessary. Retention periods depend on the type of data and legal requirements:
| Data Type | Retention Period |
|---|---|
| Individual care records | Duration of service plus 8 years |
| Financial & payment records | 7 years (HMRC requirements) |
| Staff & volunteer records | 6 years after employment ends |
| Safeguarding records | 10 years (or longer if required) |
| Website analytics | Up to 26 months |
| Portal account data | Duration of service plus 12 months |
Once retention periods expire, data is securely shredded, deleted, or permanently anonymised. Where records are subject to legal requirements or ongoing enquiries, retention is extended until resolved.
12 Data Security
We take safeguarding your personal information very seriously. We maintain robust technical and organisational security measures to protect your data against loss, theft, misuse, or unauthorised access, including:
- Encrypted digital storage for sensitive health and care details;
- Secure HTTPS web encryption across our entire website and Portal;
- Role-based access controls: staff only see information necessary for their daily care duties;
- Regular data protection and confidentiality training for all staff and volunteers;
- Strong password standards and multi-factor authentication for Portal accounts;
- Encrypted daily backups to prevent accidental data loss;
- Firewalls and anti-malware safeguards across all organisation computers;
- Clear incident response plans to address any potential security issues quickly.
In the rare event of a data breach that could present a risk to your rights, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected individuals promptly.
13 Your Rights Under UK GDPR
Under UK data protection law, you have specific rights regarding your personal information:
Right to be Informed
You have the right to know how your information is collected and used (this privacy policy fulfils that right).
Right of Access
You can request a copy of the personal information we hold about you (a Subject Access Request).
Right to Rectification
You can ask us to update or correct any inaccurate or incomplete details.
Right to Erasure
You can ask us to delete your information in certain circumstances (the right to be forgotten).
Right to Restrict Processing
You can ask us to pause using your data while a question or concern is resolved.
Right to Data Portability
You can ask us to transfer your data to you or another service provider in a reusable format.
Right to Object
You can object to us processing your data based on legitimate interests or for direct communications.
Right to Withdraw Consent
Where you have given consent, you can withdraw it at any time.
Rights Regarding Automated Decision-Making
You have the right not to be subject to decisions made solely by automated computer processing.
To exercise any of these rights, please contact us using the details in Section 16. We will respond within one month as required by UK GDPR. In rare, complex situations, we may extend this by up to two additional months and will write to explain why.
If you feel we have not handled your data fairly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). We would, however, welcome the opportunity to resolve any concerns with you directly first.
14 Children's Data
Our services are designed for adults. We do not knowingly collect personal information from children under the age of 16 through our website. If you believe a child has submitted information via our website forms, please contact us so we can delete it immediately.
Where a young person under 18 attends Adult Day Centre as an individual in exceptional circumstances, their information is collected with the explicit consent of a parent or legal guardian and handled with the same care as data for adult individuals.
15 Changes to This Policy
We may update this privacy policy occasionally to reflect updates in our care practices or changes in data protection laws. Any updated version will be published here with a revised "Last updated" date at the top of the page.
If we make significant changes that affect individuals using our services, we will notify you directly by letter or email. Continued use of our website or services after updates are published signifies acceptance of the revised policy.
16 Contact Us & ICO
If you have any questions about this privacy policy, wish to exercise your data protection rights, or want to discuss how we handle your personal details, please get in touch:
Adult Day Centre: Data Protection
VaLu Business Park, Ashbourne Rd
Cheadle, Staffordshire, ST10 1HF
Tel: 0800 612 8825
Email: contact@adultdaycare.org.uk
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
Email: casework@ico.org.uk
Website: ico.org.uk
Staffordshire County Council: Data Protection
Data Protection Officer
Information Governance Unit
1 Staffordshire Place, Stafford, ST16 2DH
Email: DPO@staffordshire.gov.uk
Tel: 0300 111 8000
Staffordshire: Adult Safeguarding
Tel: 0345 604 2719 (Mon to Fri, 9am to 5pm)
Out of hours: 0345 604 2886 (Emergency Duty)
Text: 07815 492613